On Sat, 12 Sep 2026 14:09:06 +0100, Aamir Ahmed wrote:
> hw_data->hws[] is annotated with __counted_by(num), so hw_data->num
> must hold the element count before the array is accessed.
> ipq_cmn_pll_register_clks() assigns it only after storing the fixed
> rate output clocks and the CMN PLL, and the unwind loop under
> unregister_fixed_clk reads .hws[] with .num still zero. Both are
> out-of-bounds accesses under CONFIG_UBSAN_BOUNDS.
>
> [...]
Applied, thanks!
[1/1] clk: qcom: ipq-cmn-pll: Assign .num before accessing .hws
commit: 9ea48293af5be389f6c6ca9c9654a0ad52a42f54
Best regards,
--
Bjorn Andersson <[email protected]>